diff --git a/.github/actions/prepare/action.yml b/.github/actions/prepare/action.yml index f2c2687a..42aabf1c 100644 --- a/.github/actions/prepare/action.yml +++ b/.github/actions/prepare/action.yml @@ -45,7 +45,7 @@ runs: uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: /mnt/kryptik/sources - key: sources-v2-${{ hashFiles('sources.lock') }} + key: sources-v3-${{ hashFiles('sources.lock') }} # A changed lock restores the previous set and fetches only what is # new; every file is still hashed against the lock. restore-keys: ${{ inputs.sources == 'fetch' && 'sources-' || '' }} @@ -55,6 +55,9 @@ runs: run: | make sources ./tools/prune-sources.sh + # The signatures too, so the set this job saves is the one CI's + # signature gate reads from disk; this pass is not the verdict. + ./tools/verify-signatures.sh > /dev/null 2>&1 || true # Saved as soon as the set is verified, not when the job ends: a job that # fails later would otherwise fetch the lock's new files again next time. @@ -62,4 +65,4 @@ runs: uses: actions/cache/save@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: /mnt/kryptik/sources - key: sources-v2-${{ hashFiles('sources.lock') }} + key: sources-v3-${{ hashFiles('sources.lock') }} diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8a123589..b678181e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -133,15 +133,19 @@ jobs: uses: actions/cache/restore@caa296126883cff596d87d8935842f9db880ef25 # v5.1.0 with: path: /mnt/kryptik/sources - key: sources-v2-${{ hashFiles('sources.lock') }} + key: sources-v3-${{ hashFiles('sources.lock') }} restore-keys: | sources- + # The signatures are fetched here too, into the set the cache keeps: + # the gate below then reads them from disk instead of asking sixty + # hosts again on every run. What this pass says is not the verdict. - name: Fetch and verify the sources if: steps.sources.outputs.cache-hit != 'true' run: | make sources ./tools/prune-sources.sh + ./tools/verify-signatures.sh > /dev/null 2>&1 || true # Not from a pull request: its cache is scoped to its merge ref, so every # one whose lock differs from main's would keep a whole copy of its own. diff --git a/tools/verify-signatures.sh b/tools/verify-signatures.sh index cd9968d9..317182f1 100755 --- a/tools/verify-signatures.sh +++ b/tools/verify-signatures.sh @@ -714,6 +714,13 @@ verify_detached() { report "$name" no-signature-upstream "no ${suffix} published beside the tarball" return fi + # A host can answer a busy runner with a page in place of the file: what + # came back is not kept, and the file is asked for once more. + if ! is_pgp_signature "$sig"; then + rm -f "$sig" + [[ "${KRYPTIK_SIGCHECK_SELFTEST:-0}" == "1" ]] || sleep 5 + quiet_fetch "$sigurl" "$sig" || rm -f "$sig" + fi if ! is_pgp_signature "$sig"; then rm -f "$sig" warn "${name}: the published ${suffix} is not an OpenPGP signature"